Exam 5v0-3521 All QuestionsBrowse all questions from this exam
Question 50

An administrator deployed vRealize Operations and has been tasked with ensuring that the VMware SDDC remains compliant to the VMware vSphere Security Configuration Guide. The compliance benchmark is showing that the VMware SDDC is not completely compliant to the standards.

Which three symptoms could have triggered a compliance alert? (Choose three.)

    Correct Answer: A, C, F

    The compliance alert could be triggered by several symptoms. One possible cause is that the lockdown mode on a vSphere ESXi host is set to Disabled, as lockdown mode is a security feature that restricts direct access and it's recommended to be enabled. Another potential cause is that the SNMP service on a vSphere ESXi host is set to Disabled, which can be against the security guidelines if SNMP monitoring is required to ensure proper management and compliance. Additionally, having the Forged Transmit policy set to allow on a Distributed Port Group could be insecure as it allows forged Ethernet frames to be sent, which can undermine network security. Hence, the combination of these three factors aligns with common security guidelines and why they would trigger a compliance alert.

Discussion
cam4l3onOptions: AEF

AEF, checked in hardening guide: https://core.vmware.com/vmware-vsphere-7-security-configuration-guide

koso77Options: ACF

I think its correct according the hardening document.

koso77

Correcting myself ABF

r3nt0nn

I think AEF is the correct.